[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cpx] Security Breach!



Ok, I am worried. I did not even stop to check if this was in the archives or not.

I was just logged into CPX as the "server admin user". Just for kicks I decided to try to access a file that should not have been accessible at all. Before I accessed the file, it looked like this:

-rw-------   1 root         wheel           1584 Jan 25 09:11 secrets.txt

To my shock and horror I was able to view the file in CPX (fortunately I was using HTTPS). After I accessed the file it looked like this:

-rw-rw----   1 root         www             1584 Jan 25 09:11 secrets.txt

Ummmm.... does anyone else see the major security issue(s) here?!

Is this a known bug? Is this a feature? If so, it is a terrible feature, IMESHO.

Thanks,
Jonathan
======================================================================
This is <cpx@xxxxxxxxxxxxx>      <http://www.groupmail.org/lists/cpx/>
Before posting a question, please search the archives (see above URL).


Home | Main Index | Thread Index
Match: Format: Sort by:
Search: